Hacker News new | ask | show | jobs
by matoro 1837 days ago
While this is true, the overwhelming majority of these incidents do not use or require zero-days. The attack vector is nearly always basic phishing/social engineering, or wildly misconfigured/unpatched systems exposed to the internet. Implementing a bare-bones security program, or giving an existing security program the tools & authority to enforce policies, would cut down on ransomware incidents by a factor of 5-10, easily, without touching cryptocurrency in the slightest.